Item detail
github.com

snyk/agent-scan

RepoRadar surfaced snyk/agent-scan — a developer tool — into the Radar section, where it sits at Gold tier with a 'try now' verdict. Its strongest signal is workflow potential, scored 9.9 out of 10.

Score8.4
Popularity82.0
Riskconditional
TierGold
Score breakdown
Usefulness8.0
Novelty9.0
Momentum8.0
Maturity8.3
Open-source/build8.4
Evidence7.2
Workflow potential9.9
Setup ease8.8

Popularity is tracked separately. Support, ads, sponsorships, and tips never affect these signals.

Why it matters

Useful for security teams that want one CLI to inventory and audit every MCP server, harness, and agent skill installed on a developer machine, and to flag prompt-injection or data-exfiltration patterns before they leak into production. Install via pip, run `snyk-agent-scan` against a config, and pipe the findings into your existing vulnerability dashboard.

Who should use it

security teams that need one CLI to inventory and audit every MCP server, harness, and skill on a developer machine platform teams building threat-detection pipelines for the agent-skill ecosystem Snyk users who want the same vuln-scanning workflow extended to AI agent components DevSecOps leads who want to detect prompt-injection patterns and data-exfiltration attempts before MCP servers reach production compliance teams building evidence for AI-risk frameworks that require documented adversarial testing

Who should skip it

Pass on snyk/agent-scan if its scope or audience does not match what your team is building right now.

About this signal

snyk/agent-scan is tracked by RepoRadar as a developer tool in the Radar section. First seen 2026-06-17; the source record was last checked on 2026-06-17. The current verdict is 'try now' with a Gold tier and easy setup difficulty. snyk/agent-scan leads on workflow potential (9.9) and novelty (9.0); its lowest signal is evidence quality (7.2), so factor that in before investing setup time. This page summarizes the public evidence on the linked source page and states where additional review is still needed.

How this item is evaluated

The snyk/agent-scan record combines a 8.4/10 composite score with separate popularity (82.0), risk (conditional), and setup (easy) signals. See the scoring methodology for the current weights and evidence definitions.

Putting this into practice? Read How to vet an AI agent or MCP server before you wire it in for the checklist behind this score.

Risk explanation

scanning MCP configs will execute the commands they declare — run scans inside a sandbox or disposable environment when evaluating third-party configs; experimental CLI output (severity labels, issue codes, response structure) may change between releases — don't bake field names into production dashboards.

Evidence links
Closest alternatives / related signals
agent-security mcp skills prompt-injection vulnerability-scanner inventory snyk python
Verification record

What RepoRadar actually verified

Discovered

Automated discovery and source capture. Last checked 2026-08-14T00:34:39Z.

No editorial or hands-on review is claimed. This record remains at Discovered.

Verification sources

Longitudinal intelligence

How this decision record is moving

Raw history JSON →

49 dated snapshots retained from 2026-06-17 through 2026-08-14; see the snapshot index for explicit coverage gaps. Stars, version, release, pricing, integration, risk, maintenance, verdict, score, and momentum fields remain explicit even when a source has not reported them. Repository momentum is a normalized 0–10 RepoRadar signal; GitHub stars appear only where the popularity monitor retained exact timestamped observations.

RepoRadar score8.4 current · +0.0 net
Repository momentum9.3 current · +1.3 net
GitHub stars (observed)2,909 current · +135 net
GitHub stars2,909 exact observation
Versionv0.6.0-snapshot-6e2d290-1511
Last release2026-08-13T14:11:23Z
Maintenanceactive
Current riskconditional
Current verdicttry now
Pricing baselineNo structured commercial pricing baseline
Pricing checkedNot applicable or not recorded
Pricing freshnessNo dated commercial pricing review
Integrations baselineModel Context Protocol

Recent dated points

DateScoreMomentumStarsRiskVerdictMaintenance
2026-08-148.49.32,909conditionaltry nowactive
2026-08-138.49.32,909conditionaltry nowactive
2026-08-128.49.32,906conditionaltry nowactive
2026-08-118.49.32,899conditionaltry nowactive
2026-08-108.49.32,897conditionaltry nowactive
2026-08-098.49.32,893conditionaltry nowactive
2026-08-088.49.32,887conditionaltry nowactive
2026-08-078.49.02,852conditionaltry nowactive
2026-08-068.48.0Not recordedconditionaltry nownot recorded
2026-08-058.48.0Not recordedconditionaltry nownot recorded
2026-08-048.49.02,852conditionaltry nowactive
2026-08-038.49.02,852conditionaltry nowactive

Why the record changed

version changed

Version changed: v0.5.17 → v0.6.0-snapshot-6e2d290-1511.

stars changed

Stars changed: 2906 → 2909.

stars changed

Stars changed: 2899 → 2906.

version changed

Version changed: v0.5.17-snapshot-6e2d290-1483 → v0.5.17.

stars changed

Stars changed: 2897 → 2899.

stars changed

Stars changed: 2893 → 2897.

stars changed

Stars changed: 2887 → 2893.

stars changed

Stars changed: 2852 → 2887.

version changed

Version changed: v0.5.16-snapshot-6e2d290-1473 → v0.5.17-snapshot-6e2d290-1483.

stars changed

Stars changed: 2851 → 2852.

version changed

Version changed: v0.5.15 → v0.5.16-snapshot-6e2d290-1473.

stars changed

Stars changed: 2845 → 2851.